Operating in a body area network around a smartphone user, wearables serve a variety of commercial, medical and personal uses. Depending on a certain smartphone application, a wearable can capture sensitive data about the user and provide critical, possibly life-or-death, functionality. When using wearables, security problems might occur on hardware/software of wearables, connected phone apps or web services devices, or Bluetooth channels used for communication. This paper develops an open source platform called SecuWear for identifying vulnerabilities in these areas and facilitating wearable security research to mitigate them. SecuWear supports the creation, evaluation, and analysis of security vulnerability tests on actual hardwares. Extending earlier results, this paper includes an empirical evaluation that demonstrates proof of concept attacks on commercial wearable devices and shows how SecuWear captures the information necessary for identifying such attacks. Also included is a process for releasing attack and mitigation information to the security community.
可穿戴设备在智能手机用户周围的体域网中运行,具有多种商业、医疗和个人用途。根据特定的智能手机应用程序,可穿戴设备可以捕获有关用户的敏感数据,并提供关键的、可能关乎生死的功能。在使用可穿戴设备时,可穿戴设备的硬件/软件、连接的手机应用程序或网络服务设备,或者用于通信的蓝牙通道可能会出现安全问题。本文开发了一个名为SecuWear的开源平台,用于识别这些领域的漏洞,并促进可穿戴设备安全研究以缓解这些问题。SecuWear支持在实际硬件上创建、评估和分析安全漏洞测试。在先前成果的基础上,本文包括一项实证评估,该评估展示了对商用可穿戴设备的概念验证攻击,并展示了SecuWear如何捕获识别此类攻击所需的信息。还包括一个向安全社区发布攻击和缓解信息的流程。